MISP / misp-taxonomies

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.
https://www.circl.lu/doc/misp-taxonomies/
Other
260 stars 134 forks source link

Add 'course-of-action:passive=nodiscover' #272

Closed andurin closed 7 months ago

andurin commented 7 months ago

Hi,

I'm on a use case where we want to search attributes regularly on historical data as some kind of default action for new attributes. On some rare cases we want to exclude specific (noisy) attributes from that default process.

The Course of Action taxonomy would match quiet good here but I would need a specific tag to exclude that noisy IOCs.

What do you think about this change?

Regards, Hendrik

adulau commented 7 months ago

It's indeed a very good point. Thanks for the contribution.